Security: Microsoft Blunders and Ubiquiti
-
A ‘high severity’ TikTok vulnerability allowed one-click account hijacking
The bug and its resulting attack, labelled a “high severity vulnerability,” could have been used to hijack the account of any TikTok user on Android without their knowledge, once they clicked on a specially crafted link. After the link was clicked, the attacker would have access to all primary functions of the account, including the ability to upload and post videos, send messages to other users, and view private videos stored in the account.
-
Azure: Ubuntu VMs paralyzed by systemd update, Kubernetes services disrupted
A recent systemd update creates an error when resolving DNS requests on virtual machines with Ubuntu Bionic Beaver (version 18.04). Systemd version 237-3ubuntu10.54 contains a bug that causes network connections to drop. The automatic installation of the update on VMs in Azure led to various failures. The Azure Kubernetes Service (AKS) in particular is severely affected globally. The Ubuntu and Azure teams are working to fix the bug and its impact. The problem is limited to Ubuntu 18.04.
-
Final Thoughts on Ubiquiti
Last year, I posted a series of articles about a purported “breach” at Ubiquiti. My sole source for that reporting was the person who has since been indicted by federal prosecutors for his alleged wrongdoing – which includes providing false information to the press.